Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3452 articles · 142284 vulns · 36/41 feeds (7d)
← Back to list
5.9
CVE-2026-42316EXPLOITEDPATCHED
microsoft · kafka-sink-azure-kusto

KQL injection via kusto.tables.topics.mapping in kafka-sink-azure-kusto

Description

A vulnerability classified as problematic was found in Azure kafka-sink-azure-kusto up to 5.2.2. Affected by this vulnerability is an unknown functionality of the component Connector Configuration Handler. The manipulation results in improper neutralization of special elements in data query logic. This vulnerability is known as CVE-2026-42316. It is possible to launch the attack remotely.

Affected Products

VendorProductVersions
microsoftkafka-sink-azure-kusto< 5.2.3, < 5.2.2

References

  • https://github.com/Azure/kafka-sink-azure-kusto/security/advisories/GHSA-c9mr-mqvh-6wgj(x_refsource_CONFIRM)
  • https://github.com/Azure/kafka-sink-azure-kusto/pull/155(x_refsource_MISC)
  • https://github.com/Azure/kafka-sink-azure-kusto/releases/tag/v5.2.3(x_refsource_MISC)

Related News (1 articles)

Tier C
VulDB2h ago
CVE-2026-42316 | Azure kafka-sink-azure-kusto up to 5.2.2 Connector Configuration data query logic injection
→ No new info (linked only)
CVSS 3.15.9 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N/E:P/RL:O/RC:C
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
5.2.3
CWECWE-943
PublishedMay 11, 2026
Last enriched2h agov2
Trending Score52
Source articles1
Independent1
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-40372EXP
ASP.NET Core Elevation of Privilege Vulnerability
Trending: 62
HIGHCVE-2026-39836EXP
Panic in Dial and LookupPort when handling NUL byte on Windows in net
Trending: 59
HIGHCVE-2026-26164EXP
M365 Copilot Information Disclosure Vulnerability
Trending: 43
HIGHCVE-2026-26129EXP
M365 Copilot Information Disclosure Vulnerability
Trending: 43
CRITICALCVE-2026-33109EXP
Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability
Trending: 42

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
May 11, 2026
Discovered by ZDM
May 11, 2026
Actively Exploited
May 11, 2026
Patch Available
May 11, 2026
Updated: description, affectedVersions, severity, activelyExploited, patchAvailable
May 11, 2026

Version History

v2
Last enriched 2h ago
v2Tier C2h ago

Updated description with new details, changed affected versions to < 5.2.2, updated severity to HIGH, and noted that the vulnerability is actively exploited.

descriptionaffectedVersionsseverityactivelyExploitedpatchAvailable
via VulDB
v13h ago

Initial creation